<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for Chromium</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2018:2134-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2018-07-28T18:12:44Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2018-07-28T18:12:44Z</InitialReleaseDate>
    <CurrentReleaseDate>2018-07-28T18:12:44Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for Chromium</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for Chromium to version 68.0.3440.75 fixes multiple issues.

Security issues fixed (boo#1102530):

- CVE-2018-6153: Stack buffer overflow in Skia
- CVE-2018-6154: Heap buffer overflow in WebGL
- CVE-2018-6155: Use after free in WebRTC
- CVE-2018-6156: Heap buffer overflow in WebRTC
- CVE-2018-6157: Type confusion in WebRTC
- CVE-2018-6158: Use after free in Blink
- CVE-2018-6159: Same origin policy bypass in ServiceWorker
- CVE-2018-6161: Same origin policy bypass in WebAudio
- CVE-2018-6162: Heap buffer overflow in WebGL
- CVE-2018-6163: URL spoof in Omnibox
- CVE-2018-6164: Same origin policy bypass in ServiceWorker
- CVE-2018-6165: URL spoof in Omnibox
- CVE-2018-6166: URL spoof in Omnibox
- CVE-2018-6167: URL spoof in Omnibox
- CVE-2018-6168: CORS bypass in Blink
- CVE-2018-6169: Permissions bypass in extension installation
- CVE-2018-6170: Type confusion in PDFium
- CVE-2018-6171: Use after free in WebBluetooth
- CVE-2018-6172: URL spoof in Omnibox
- CVE-2018-6173: URL spoof in Omnibox
- CVE-2018-6174: Integer overflow in SwiftShader
- CVE-2018-6175: URL spoof in Omnibox
- CVE-2018-6176: Local user privilege escalation in Extensions
- CVE-2018-6177: Cross origin information leak in Blink
- CVE-2018-6178: UI spoof in Extensions
- CVE-2018-6179: Local file information leak in Extensions
- CVE-2018-6044: Request privilege escalation in Extensions
- CVE-2018-4117: Cross origin information leak in Blink

The following user interface changes are included:

- Chrome will show the &amp;quot;Not secure&amp;quot; warning on all plain HTTP pages</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      <Description>E-Mail link for openSUSE-SU-2018:2134-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub for SUSE Linux Enterprise 12 SP2">
      <Branch Type="Product Name" Name="SUSE Package Hub for SUSE Linux Enterprise 12 SP2">
        <FullProductName ProductID="SUSE Package Hub for SUSE Linux Enterprise 12 SP2">SUSE Package Hub for SUSE Linux Enterprise 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="chromedriver-68.0.3440.75-61.1">
      <FullProductName ProductID="chromedriver-68.0.3440.75-61.1">chromedriver-68.0.3440.75-61.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="chromium-68.0.3440.75-61.1">
      <FullProductName ProductID="chromium-68.0.3440.75-61.1">chromium-68.0.3440.75-61.1</FullProductName>
    </Branch>
    <Relationship ProductReference="chromedriver-68.0.3440.75-61.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub for SUSE Linux Enterprise 12 SP2">
      <FullProductName ProductID="SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1">chromedriver-68.0.3440.75-61.1 as a component of SUSE Package Hub for SUSE Linux Enterprise 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="chromium-68.0.3440.75-61.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub for SUSE Linux Enterprise 12 SP2">
      <FullProductName ProductID="SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1">chromium-68.0.3440.75-61.1 as a component of SUSE Package Hub for SUSE Linux Enterprise 12 SP2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2018-4117</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4117.html</URL>
        <Description>CVE-2018-4117</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1088182</URL>
        <Description>SUSE Bug 1088182</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6044</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6044.html</URL>
        <Description>CVE-2018-6044</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077571</URL>
        <Description>SUSE Bug 1077571</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.</Note>
    </Notes>
    <CVE>CVE-2018-6153</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6153.html</URL>
        <Description>CVE-2018-6153</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6154</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6154.html</URL>
        <Description>CVE-2018-6154</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6155</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6155.html</URL>
        <Description>CVE-2018-6155</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6156</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6156.html</URL>
        <Description>CVE-2018-6156</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6157</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6157.html</URL>
        <Description>CVE-2018-6157</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.</Note>
    </Notes>
    <CVE>CVE-2018-6158</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6158.html</URL>
        <Description>CVE-2018-6158</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6159</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6159.html</URL>
        <Description>CVE-2018-6159</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6161</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6161.html</URL>
        <Description>CVE-2018-6161</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.</Note>
    </Notes>
    <CVE>CVE-2018-6162</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6162.html</URL>
        <Description>CVE-2018-6162</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.</Note>
    </Notes>
    <CVE>CVE-2018-6163</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6163.html</URL>
        <Description>CVE-2018-6163</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.</Note>
    </Notes>
    <CVE>CVE-2018-6164</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6164.html</URL>
        <Description>CVE-2018-6164</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.</Note>
    </Notes>
    <CVE>CVE-2018-6165</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6165.html</URL>
        <Description>CVE-2018-6165</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.</Note>
    </Notes>
    <CVE>CVE-2018-6166</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6166.html</URL>
        <Description>CVE-2018-6166</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.</Note>
    </Notes>
    <CVE>CVE-2018-6167</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6167.html</URL>
        <Description>CVE-2018-6167</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6168</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6168.html</URL>
        <Description>CVE-2018-6168</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.</Note>
    </Notes>
    <CVE>CVE-2018-6169</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6169.html</URL>
        <Description>CVE-2018-6169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A bad cast in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.</Note>
    </Notes>
    <CVE>CVE-2018-6170</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6170.html</URL>
        <Description>CVE-2018-6170</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6171</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6171.html</URL>
        <Description>CVE-2018-6171</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.</Note>
    </Notes>
    <CVE>CVE-2018-6172</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6172.html</URL>
        <Description>CVE-2018-6172</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.</Note>
    </Notes>
    <CVE>CVE-2018-6173</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6173.html</URL>
        <Description>CVE-2018-6173</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.</Note>
    </Notes>
    <CVE>CVE-2018-6174</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6174.html</URL>
        <Description>CVE-2018-6174</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.</Note>
    </Notes>
    <CVE>CVE-2018-6175</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6175.html</URL>
        <Description>CVE-2018-6175</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6176</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6176.html</URL>
        <Description>CVE-2018-6176</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</Note>
    </Notes>
    <CVE>CVE-2018-6177</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6177.html</URL>
        <Description>CVE-2018-6177</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.</Note>
    </Notes>
    <CVE>CVE-2018-6178</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6178.html</URL>
        <Description>CVE-2018-6178</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.</Note>
    </Notes>
    <CVE>CVE-2018-6179</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-68.0.3440.75-61.1</ProductID>
        <ProductID>SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-68.0.3440.75-61.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2018-07/msg00051.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-6179.html</URL>
        <Description>CVE-2018-6179</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1086124</URL>
        <Description>SUSE Bug 1086124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102530</URL>
        <Description>SUSE Bug 1102530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1107235</URL>
        <Description>SUSE Bug 1107235</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
